> TODAY'S SUMMARY (36 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities. A major incident involved hackers hijacking Microsoft's official X account to promote a cryptocurrency scheme, showcasing the ongoing risks of social media exploitation. Additionally, a critical zero-day vulnerability in Fortinet's FortiMail is actively being exploited, prompting urgent action from users and inclusion in the U.S. CISA's Known Exploited Vulnerabilities catalog. On the espionage front, a China-aligned group has been phishing AI policy experts by impersonating US officials, emphasizing the trend of targeting high-profile individuals. Meanwhile, AI agents are increasingly being linked to SQL injection attacks against government sites, raising concerns about the security of AI applications. Lastly, law enforcement has made arrests in the KillSec ransomware group, reflecting ongoing efforts to combat cybercrime.
|
// AI-powered summary generated at 12:00
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.
The odd part: the group that took the money calls itself Kairos, but...
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general purpose scripting language, could result in memory corruption. For the stable distribution (trixie), this problem has been fixed in
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.
"The campaign remains active, and new mali...
Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.
Attested TLS: the handshake that can't prove who's on the other end
Information published.
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and securit...
Australian Cyber Aware - As It Was 2606 - June 2026. Aggregated listing of Australian and New Zealand cybersecurity, privacy, and AI risks developments identified during May 2026. It includes cybersecurity incidents, regulatory updates, news stories, audit findings, and broader industry development...
Une cyberattaque a touché un partenaire logistique de De Bijenkorf, entraînant des retards dans les commandes, les retours et les remboursements. Le grand magasin enquête sur la possibilité que les attaquants aient également accédé aux données personnelles des clients. Le grand magasin d'appuie sur...
Multiple security vulnerabilities were discovered in OpenVPN, which could result in denial of service. For the stable distribution (trixie), these problems have been fixed in version 2.6.14-1+deb13u3. We recommend that you upgrade your openvpn packages.
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards.
The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, d...
A former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly...
USN-8496-1 introduced a regression in cifs-utils
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.
Bad Epoll sits in the same small stretch of kernel code where Anthropic's mos...
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls.
Avalon combines credential collection, lateral movement, remote access, reco...
USN-8496-1 fixed a vulnerability in cifs-utils. Unfortunately, the fix
introduced a regression with Kerberos mounts. This update reverts the
security update until a complete fix is available.
We apologize for the inconvenience.
Original advisory details:
It was discovered that cifs-utils incorre...
A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. [...]
La Commission nationale de l'informatique et des libertés (CNIL) a rendu public l'ordre du jour de sa séance plénière du 4 juin 2026.
Partie I (avec débats): :
* Présentation des résultats de l’enquête « DPO et IA » par des représentants du ministère du Travail (DGEFP) et de l’AFPA ;
* Comm...
L'autorité suédoise a prononcé une réprimande à l'encontre de la police pour un manquement à son obligation d'information des voyageurs dans une zone de contrôle aux frontières, l'information n'étant disponible que sur son site internet sans aucun renvoi sur place.Faits et contexteL'autorité suédois...
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.
According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legit...